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Abstract. We have developed a scheme to generate, control, transmit and measure entangled photonic qutrits (two photons 
each of dimension d = 3). A Bell test of this source has previously been reported elsewhere [1], therefore, here we focus on 
how the control of the system is realized. Motivated by these results, we outline how the scheme can be used for two specific 
quantum protocols, namely key distribution and coin tossing and discuss some of their advantages and disadvantages. 



Performing quantum communication with high-dimensional systems would appear to be an obvious and straight- 
forward extension to many of the qubit protocols that have driven quantum information science in recent years. 
There have been theoretical proposals for Quantum Key Distribution (QKD) [2] with greater security [3] as well 
as specific proposals for qutrits such as quantum coin tossing [4]. Fundamentally, high-dimensional Bell inequalities 
have revealed greater violations of non-locality [5] while increasing the dimensions of the entangled systems has been 
shown to facilitate closing the detection loop-hole [6] for such tests. Optics has been able to provide a realistic test-bed 
for these proposals with several different schemes being realized for generating high-dimensional entanglement [7, 8] 
as well as the scheme presented here [1,9]. 

This source of entangled qutrits is analogous to the energy-time qubit arrangement of Franson [10]. The experi- 
mental scheme has been developed for telecom wavelengths and with proven long distance quantum communication 
architecture [11, 12] to optimise the usefulness of this high dimensional entanglement resource. We have already per- 
formed a Bell-type test on this system [1] where we determined a means of infeiTing a violation from the interference 
fringe visibility. We found a net visibility of V„e,= 0.979 ± 0.006 coiTesponding to a violation of the VBeii limit by 
34 a. From a practical perspective, it is interesting to discuss how the symmetry constraints were met and controlled 
in this set-up to achieve the violation. In doing this we also explore some of the subspaces of these high-dimensional 
states and we show how these correspond to the states required for quantum coin tossing. We also outline how we can 
use this scheme for QKD. We also briefly highlight some of the positive as well as negative aspects of these higher 
dimensional states in the case of these proposed protocols. 

The experimental set-up is illustrated in the schematic of Fig. 1 . We use energy-time entangled photon pairs created 
at telecom wavelengths, via a PPLN waveguide (courtesy of the Uni. of Nice) [13], and two three-arm interferometers 
to generate and analyze entangled qutrits. For each interferometer we can define a phase vector consisting of the 
two independent phases, e.g. the relative phases between the short-medium (m) and short-long (1), path-lengths. 
Coincidence measurements at the outputs of the interferometers project onto entangled qutrit states defined when the 
photons take the same path, i.e. short-short, medium-medium or long-long in each of Alice and Bob's interferometers. 
In complete analogy with the Franson qubit arrangement [10], we use a continuous wave (CW) laser where the long 
coherence length does not provide a well defined creation time for the photon pairs. The coherence length of the photon 
pairs is much longer than the path-length differences in the interferometers, while the coherence length of the single 
photons is much less, such that no single-photon interference takes place. We have set the path-length differences, 
I — m K, m — s, corresponding to a time difference of 1.2 ns. An arrival-time-difference histogram with five peaks, 
due to all the possible path combinations, like that on the right in Fig.l is generated for each detector combination. 
Therefore, when we select events in the central peak, i.e.. Af = ^ ffi ~ 0, these correspond to the post-selection of 
states of the form 




FIGURE 1. (left) Schematic of experimental arrangement for energy-time entangled qutrits. (right) Histogram of the photon 
arrival time difference at pairs of Alice and Bob's detectors. The labeling denotes the possible interferometer-path combinations. 



Here «,„,«/ and j3,„,)3/, represent the phases in AHce and Bob's medium and long interferometer arms. Xjl and Xjk 
are muhiples of 2n/3 due to the symmetry of the 3x3 couplers and depends on the paths taken by the photons in 
the interferometers and which output (detector), j,k e {0, 1,2}^ g. For more technical as well as theoretical details 
see refs [1, 9, 14]. Maximally entangled qutrits require that \cs\^ = |c,„p — |c/p, which simply corresponds to having 
symmetric splitting ratios for the fiber couplers in the interferometers. We can then observe the three orthogonal states 
corresponding to the three different coincidence detections, 0^0^, O^Ib, 0a2b, or their cyclic permutations. When the 
phases are scanned the coincidences vary as a function of Alice and Bob's phase vectors. 

The first question that arises now is - how do we characterise the set-up? Being an interferometric arrangement the 
most obvious solution is to vary the phases and observe the interference fringe visibility, the normalized difference 
between the maximum and minimum intensities/coincidence rates. Classically, the visibility is defined by y = 
(Imax — Imin) I {Inmx + Imin)- To obtain a maximum of 1 we need /„„■„ = 0. This is theoretically trivial in the case of 
qubits with only one phase. With two phases, as in the qutrit scenario, we can always set one of the phases such that 
changing the other never results in a minimum of zero. Therefore, there are constraints on how the two phases must 
be related to obtain the maximum visibility. Practically this presents a problem since the phase is controlled here via 
temperature and thus any variation in temperature implies a change in the phase. This means that a phase of "0" at the 
beginning of the experimental run may not be "0" at the end due to temperature drift. We also generally scan through 
all phase settings, thus, we need a means of determining how the two phases are varying in relation to one another. 

To this end we revisit the histogram of five peaks in Fig.l. The two peaks either side of the central peak at 
At — tA ~ tB = ±1 .2 Hi, the " left" and the " right", provide us with a control solution. This time difference is defined by 
the path-length differences between the short-medium and medium-long arms of the interferometers. These satellite 
peaks correspond to projections onto sub-spaces of the entangled qutrit Hilbert space. For example, the 0^0^ detector 
combination has the unnormalised states for the left, \ Vob)' right, \ Voo)' peaks (for simplicity we set j3j = 0): 

I v/oo> °' l"«> + e'^'^oo-^^'/^'^llm) I Xj/l^o) oc \sm) + e'(i'oo+2'i/3) |^/) . (2) 

By defining the phases as = ai — a,„ and <t>QQ = a,„ + 2n/3, we can rewrite the states of the central peak 
as, I Vbo) °^ |00) + exp[/<I>QQ] 1 11) + exp[/(<I>QQ + Oqo)] 1^2), and in general, for all detector combinations, we find the 
probabiUties for coincidence detection given by 

Pjk - 3 + 2A [cos{<P%) + cos{<P%) + cos{<P% + 'P^)] . (3) 

This is actually the probability associated with the mixed state, p = A| + (1 — A)//9, where / denotes 
symmetric noise [1]. The requirements for the minimum are the same, however the mixing parameter will also 
effect this minimum. Therefore, by monitoring the way the states associated with the left and right satellite peaks 
change, as we scan the phases, we can infer the relationship between the two free phases. To have Pji^ = we need 
+ ^'jit} = ±2n/3. If we parameterise this by just one of these phases, setting <P^f. — n<P^i^, we can 
consider {<P^i^,n<i>^j^, {n + l)<I>y^.} — ±2;r/3. As we see, there is a large family of possible solutions. To observe these 
effects we need to vary both of the phases at the same time and in a manner that satisfies these constraints. 

To illustrate let us consider a couple of examples. First, we have shown in Fig. 2 the case where the left phase is 
varying n « 7 times faster than the right phase. One can easily verify that this satisfies the constraints we introduced 
for Pjii = 0. The high visibility of the satellite peaks is reflected in that of the central peak where we see that the 
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FIGURE 2. (left) The coincidence counts for the left and right satellite peaks. The phase of the left peak is varying ~ 7 times 
faster than phase of the right peak, (right) The coincidence counts, recorded simultaneously, for the central peak. 

minimum approaches the noise level. What we also see, on the right of Fig. 2 (central peak), is the beating type effect 
between the two phases. When the visibility is not high, in the central peak, these satellite peaks allow us to determine 
whether this is due to the phase alignment or with standard misalignment and distinguishability problems. From a 
practical perspective this significantly facilitates the alignment of the interferometers. 

If we consider a second example we find that the simplest relationship is when both left and right vary at the same 
rate, n « 1, as depicted in Fig. 3. It turns out that this is exactly the same requirement as that needed to satisfy one of 
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FIGURE 3. Coincidence rates as in Fig. 2 with the left and right phases varying at almost the same rate, n~\. 

the symmetry constraints for the violation of the Bell inequality. The Bell test results and the relationship between the 
visibility and the CGLMP-Bell inequality [5] are derived in [1]. 

Having a source of entangled qutrits that are capable of violating a Bell inequality we may ask what we can do with 
it. Proposals have been made for performing quantum key distribution (QKD) with high-dimensional systems [2]. The 
setup illustrated in Fig.l can be easily interpreted as a qutrit QKD set-up by associating the photon pair source with 
Alice, as denoted by the dashed square. We thus have a source that can be seen to transmit heralded qutrits from 
Alice to Bob in states determined by Alice's choice of phase setting [15]. In [2] there are four bases introduced, the 
computational basis, |0), |1), |2), and three superposition bases. In this set-up we cannot use the computational basis 
without introducing switches at the input of the interferometers. The simplest, and perhaps most naive, advantage 
one gains from using high-dimensional schemes for QKD is that one sends dits of information, which, from an 
information theoretic perspective, implies more information (cZ-dimensions log2c/ bits). The security bounds also 
show significant improvement with increased dimensioins. Cerf et al [3] studied both 2-basis and + 1 basis protocols, 
considering individual and coherent attacks, and found a significant security increase scaling with the dimensions. 
Specifically for qutrits, with individual attacks, the 2-basis protocol is slightly lower, 21.13%, than the t/+ l(=4)-basis, 
22.67%, whilst for the coherent attacks the 11% Shor-Preskill error bound for qubits goes up to almost 16%. We see 
that there are definite advantages to be gained here, however, we are currently constrained by technical complications. 

There are at least two significant problems for high-dimensional schemes such as this. The first is that we have nine 



detectors that will all contribute to the QBER. Preliminary studies on the security and transmission impUcations due 
to detector noise have been made [16] but this is difficult to generalise as the results are both system and protocol 
dependent. A more fundamental problem here is the way we count "successful events", i.e. the transmission of a qutrit. 
We only look, in coincidence, at the events where the photons took the same path in each interferometer. This means 
that whenever the photons take different paths to each other they are discarded. This amounts to keeping only a third 
of the possible signal, even before one gets to basis reconciliation. Currently, qubit cryptographic protocols are quite 
capable of operation below the 11% error Umit, thus, the main benefit is due to transferring dits and not bits. 

Quantum coin tossing is another protocol where it has been found that qutrits are advantageous [4, 17]. If we 
consider the states associated with the satellite peaks and assign {s,m,l}A with {0, 1,2}^ and {s,m,l}B with {l,0,2}g, 
we can rewrite Eq.2, with appropriate choices of phases, as 

|v4) = |11)±|20)ab |v/«) = |00)±|12Ub. (4) 

Thus if Alice has a detection in the left (right) peak, projecting onto 1 1) ± |2) (|0) ± 1 1)), she prepares the state |0) ± 1 1) 
(|0) ± |2)) to send to Bob as the proposed protocol requires. Notice that the choice of the basis, left or right, is 
made randomly by the photon. Unfortunately, from a practical perspective again, the security to ensure that no one 
is cheating can be lost due to detector noise and efficiency. Barrett et al. [18J have discussed the related problem of 
loss in coin tossing and bit commitment protocols and shown that in the presence of noise a single coin-toss is not 
possible but one can generate secure bit-strings. Cheating is possible as one of the parties can take advantage of the 
statistical possibiUty of there being a photon and not detecting it, or having no photon and accidental detection, etc. 
This discussion is independent of the dimension, however a more practical analysis by Langford et al. [8] also showed 
that any security gains obtained by using qutrits over qubits was highly sensitive to the fidelity of the prepared states. 

In conclusion, we have given the results for a Bell-test performed using the entangled qutrit source presented here 
and shown some of the control techniques that can be incorporated. We have also put some practical perspective on 
some of the often cited benefits of high-dimensional systems via two specific examples, quantum key distribution and 
coin tossing. One protocol that was of great experimental motivation, that we did not discuss here, is the Byzantine 
Agreement problem. This is classically impossible, however an elegant solution was found requiring three entangled 
qutrits [19]. Unfortunately, it was recently shown that it could in fact be achieved with a simple QKD arrangement [20] . 
What this leaves us with are some very interesting and useful high-dimensional entanglement sources that are providing 
an excellent test-bed for fundamental ideas. From a quantum information perspective however we are waiting for ideas 
that really exploit the complexity that these systems have to offer. 
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